Initial commit

This commit is contained in:
Scooby Husky
2026-03-09 20:21:35 -05:00
commit aacb8eebbe
314 changed files with 21766 additions and 0 deletions
@@ -0,0 +1,44 @@
# PeerAuthentication PERMISSIVE for namespaces that receive non-mesh traffic
# The API server calls webhooks from outside the mesh (no SPIFFE identity).
# The CrowdSec firewall bouncer runs on hostNetwork (no mesh identity)
# and must connect to LAPI over plaintext.
# PERMISSIVE allows both mTLS and plaintext inbound.
---
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-apiserver-webhooks
namespace: cnpg-system
spec:
mtls:
mode: PERMISSIVE
---
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-apiserver-webhooks
namespace: mariadb-system
spec:
mtls:
mode: PERMISSIVE
---
# Netbird operator webhook receives calls from the API server
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-apiserver-webhooks
namespace: netbird-operator
spec:
mtls:
mode: PERMISSIVE
---
# CrowdSec firewall bouncer (hostNetwork DaemonSet) connects to LAPI
# from the host network namespace without a mesh identity
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-hostnetwork-bouncer
namespace: crowdsec
spec:
mtls:
mode: PERMISSIVE